Privacy Policy
Last updated: 2026-05-27.
1. Who we are
HighConvertingEmails is the operator of the Service available at highconvertingemails.com. For GDPR purposes, we are the data controller for personal data collected via the Service. Contact: privacy@highconvertingemails.com.
2. Data we collect
- Account data: name, email, password hash, organization name, billing details.
- Usage data: timestamps, feature usage, model selection, token counts. Not the email content itself unless you save a template.
- Content: drafts you save as templates, brand voice samples you upload, sequence definitions you create.
- Analytics: page views, feature interactions, device type — captured via PostHog with IP anonymized.
- Error data: stack traces and request metadata captured via Sentry on errors.
3. Lawful basis (GDPR)
- Contractual necessity: account creation, service provision, billing.
- Legitimate interest: security monitoring, fraud prevention, product analytics (aggregated).
- Consent: marketing emails (where applicable), optional analytics that exceed the essential.
4. How long we keep data
- Account data: until you delete your account, plus 30 days for restore window.
- Usage logs: 24 months for billing reconciliation and product analytics.
- Content (templates, brand voice samples): until you delete them or your account closes.
- Backups: rolling 30-day retention, expired backups destroyed.
- Legal/tax records: as required by applicable law (typically 7 years for financial records).
5. Who we share data with
We use the following sub-processors:
- Anthropic (AI processing — inputs sent for generation, outputs returned, not used for training)
- Stripe (payment processing — handles card data directly)
- Resend (transactional email)
- PostHog (product analytics, self-hosted or with EU residency option)
- Sentry (error tracking)
- Hosting infrastructure (managed European provider)
We do not sell your personal data. For data transferred outside the EEA, we rely on Standard Contractual Clauses where applicable.
6. Your rights (GDPR/CCPA)
You have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate data.
- Request deletion (subject to legal-retention requirements).
- Port your data to another provider in a machine-readable format.
- Object to processing based on legitimate interest.
- Withdraw consent where consent is the basis.
- Lodge a complaint with your supervisory authority.
To exercise any right, email privacy@highconvertingemails.com. We respond within 30 days.
7. Cookies and tracking
We use essential cookies for authentication and session management. We use PostHog with IP-anonymization enabled for product analytics. We do not run advertising trackers. Users in the EU/UK see a consent banner; non-essential tracking is off by default until consent is given.
8. Security
We encrypt customer data in transit and at rest, restrict production access to named personnel, and follow a documented incident-response process. Contact security@highconvertingemails.com with questions.
9. Children
The Service is not directed at children under 16. We do not knowingly collect personal data from children. If you believe we have, contact us at privacy@highconvertingemails.com.
10. Changes
Material changes to this policy will be announced via email at least 30 days before they take effect. Non-material changes update the "Last updated" date above.